Device posture
Evaluate endpoint health and enforce failures deliberately.
Device posture checks health evidence. Device policies configure agent behavior; access policies grant services.
Roll out a posture policy#
- Open Security → Device Posture.
- Create a baseline or scoped override.
- Choose tenant, role, group, or device scope.
- Select checks such as encryption, firewall, OS version, screen lock, EDR, or connectivity.
- Start in Monitor and review fleet impact.
- Move to Warn or Enforce only after resolving expected failures.
- For Enforce, select an action and acknowledge the impact preview when blocking.
Device, group, role, then baseline precedence determines the effective policy; order breaks ties within a scope.
Posture blocks access only when an enforcing mode and blocking-equivalent action apply. Monitor records results. Warn and a Warn User action allow access while surfacing non-compliance. Quarantine currently behaves like Block Access.
Stale or unknown evidence must not be treated as compliant. Review posture events in Audit.